Authentication and sessions

25 procedures covering login and logout, session expiry and invalidation on logout, password reset flow, remember-me, OAuth and OIDC redirect flow. Out of scope here: penetration testing of auth, SSO vendor configuration, identity provider administration.

Sessions and Cookies

Passwords and MFA

Login and Logout

Tokens and Refresh

OAuth and OIDC

Checklists

Questions people ask about this area